Instructions for limiting behavior in custom commands is confusing

With custom modes deprecated, it would be helpful to provide examples of explicitly how to tell a Custom Commond what it can and cannot do, and provide some evidence of how those instructions will be respected (e.g. an internal whitelisting process etc.).

For instance, if I say “Use playwright-mcp-extension - and no other MCP tools” will that then break some internal Cursor tools that might ordinarily work, or will it know I am referring only to MCPs that I have configured?

If I say “Edit only files in foo/, not in bar/” will it 100% respect those instructions?

The current chat agent does not respect instructions like these ordinarily - so I am inclined to ask.

Thanks!